Vulnerability priority assessment method, system, device and storage medium based on large language model

By combining large language models and digital twin technology, vulnerability triggering dependencies are identified and physical environments are simulated, which solves the limitations of semantic understanding and environment simulation in existing vulnerability assessment technologies, and achieves more accurate vulnerability prioritization assessment and security decision support.

CN121525052BActive Publication Date: 2026-04-14NINGBO ZIHE TECH CO LTD
View PDF 3 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2026-01-15
Publication Date
2026-04-14

AI Technical Summary

Technical Problem

Existing technologies struggle to identify deep semantic relationships in vulnerability description texts. Environmental risk assessments are limited to network logical partitions, failing to incorporate impact simulations of the real physical environment and lacking dynamic consideration of the real-time operating status of terminals. This results in deviations between risk assessment results and actual threats, making it difficult to provide effective support for refined and scenario-based vulnerability handling.

Method used

By using a large language model to analyze historical vulnerability assessment data to identify trigger dependencies, and combining a digital twin model to simulate the physical environment, an environmental risk coefficient is generated. Furthermore, by combining real-time hardware resource data to calculate the load risk value, multiple risk factors are integrated to assess vulnerability priority.

Benefits of technology

It achieves deep modeling of complex attack paths, improves semantic understanding capabilities, refines the restoration of the impact of the physical environment, enhances the sensitivity response to the terminal's operating status, improves the accuracy and adaptability of vulnerability ranking in real business scenarios, and supports more scientific security decisions.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121525052B_ABST
    Figure CN121525052B_ABST
Patent Text Reader

Abstract

The application relates to the technical field of large language models, and provides a vulnerability priority evaluation method, system, device and storage medium based on a large language model, which solves the problems of limited text understanding capability, limited environmental risk evaluation, biased evaluation results, and difficulty in providing effective support for fine and scenario-based vulnerability disposal. Real-time hardware resource data, vulnerability historical evaluation data and terminal physical property data are acquired; the vulnerability historical evaluation data is analyzed, trigger dependency relationships between different vulnerabilities are identified, and vulnerability chain risk values are generated; a physical environment simulation scenario in which an enterprise intranet terminal is located and a running state change process of the enterprise intranet terminal after a vulnerability is triggered are simulated, and an environmental risk coefficient is generated; a load risk value corresponding to the enterprise intranet terminal is calculated; and based on the vulnerability chain risk value, the environmental risk coefficient and the load risk value, the priority of the vulnerability in the enterprise intranet terminal is evaluated, so that the accuracy and scenario adaptability of vulnerability priority determination are improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of large language model technology, and in particular to a vulnerability priority assessment method, system, device and storage medium based on large language models. Background Technology

[0002] With the increasing complexity of enterprise IT infrastructure, especially the surge in the number of intranet terminals and the continuous evolution of network attack methods, traditional static vulnerability prioritization methods based on general vulnerability scoring systems are no longer sufficient to meet the needs of dynamic and accurate risk management. In critical areas such as industrial control, financial transactions, and medical equipment, the actual harm of vulnerabilities depends not only on their technical characteristics but also on the physical environment of the terminal, its operating load, and the combined effects with other vulnerabilities.

[0003] Current research has attempted to construct vulnerability knowledge graphs using graph-structured neural networks. By analyzing co-occurrence patterns and exploitation paths among known vulnerabilities, these graphs predict potential multi-step attack chains and calculate comprehensive risk scores. However, these existing solutions rely on pre-defined graph structures and manual features, making it difficult to identify implicit relationships not apparent in historical data and limiting their ability to understand vulnerability descriptions. Environmental risk assessments are limited to network logical partitions and fail to incorporate simulations of the impact of real physical environments. Furthermore, the lack of dynamic consideration of the real-time operational status of endpoints prevents accurate reflection of actual attack surface changes, leading to discrepancies between risk assessment results and actual threats. Consequently, these approaches struggle to provide effective support for refined and scenario-based vulnerability mitigation. Summary of the Invention

[0004] The purpose of this application is to provide a vulnerability priority assessment method, system, device, and storage medium based on a large language model, in order to solve the problems in the existing technology, such as limited ability to understand vulnerability description text, limitations in environmental risk assessment, deviation between risk assessment results and real threats, and difficulty in providing effective support for refined and scenario-based vulnerability handling.

[0005] To address the aforementioned technical problems, in a first aspect, this application provides a vulnerability priority assessment method based on a large language model, comprising:

[0006] Acquire real-time hardware resource data, historical vulnerability assessment data, and physical attribute data of enterprise intranet terminals. The historical vulnerability assessment data includes the vulnerability trigger frequency and vulnerability repair time for different vulnerabilities.

[0007] The historical vulnerability assessment data is analyzed using a large language model to identify the triggering dependencies between different vulnerabilities, and a vulnerability chain risk value is generated based on the triggering dependencies between the different vulnerabilities.

[0008] Based on the physical attribute data of the terminal, a digital twin model is used to simulate the environment of the enterprise intranet terminal and the change process of the terminal's operating status after the vulnerability is triggered, so as to generate an environmental risk coefficient.

[0009] Based on the real-time hardware resource data and the terminal physical attribute data, calculate the load risk value corresponding to the enterprise intranet terminal;

[0010] Based on the vulnerability chain risk value, the environmental risk coefficient, and the load risk value, the vulnerability priority in the enterprise intranet terminal is assessed.

[0011] Optionally, a large language model can be used to parse the historical vulnerability assessment data to identify the triggering dependencies between different vulnerabilities, including:

[0012] Using a large language model, the triggering conditions, impact results, and target terminal device types associated with each vulnerability are extracted from the historical vulnerability assessment data.

[0013] The triggering conditions, impact results, and target terminal device types of each vulnerability are correlated and matched to identify potential trigger-related vulnerabilities that belong to the same device type and whose triggering conditions and impact results are connected.

[0014] Extract the vulnerability trigger time sequence and vulnerability remediation completion time information corresponding to the potential trigger-related vulnerabilities from the historical vulnerability assessment data;

[0015] Based on the vulnerability triggering time sequence and vulnerability patching completion time information, the potential triggering associated vulnerabilities are verified to determine the triggering dependency relationship between different vulnerabilities. The verification operation includes comparing the historical triggering time of the first vulnerability with the historical triggering time of the second vulnerability in the potential triggering associated vulnerabilities, comparing the vulnerability patching completion time of the first vulnerability with the historical triggering time of the second vulnerability, and determining whether the triggering time interval between the first vulnerability and the second vulnerability is within the time range of conventional vulnerability chain triggering. The first vulnerability and the second vulnerability are any different vulnerabilities in the potential triggering associated vulnerabilities.

[0016] Optionally, based on the triggering dependencies between the different vulnerabilities, a vulnerability chain risk value is generated, including:

[0017] Based on the triggering dependency relationship between the different vulnerabilities, vulnerabilities with triggering dependency relationships are identified as confirmed associated vulnerabilities, and these confirmed associated vulnerabilities are connected to form an associated vulnerability chain.

[0018] Based on the vulnerability triggering frequency and vulnerability repair time corresponding to each confirmed associated vulnerability in the associated vulnerability chain, determine the triggering probability value and processing difficulty value of each confirmed associated vulnerability;

[0019] The total number of vulnerabilities in the associated vulnerability chain is counted, and the chain risk bonus value is determined based on the total number of vulnerabilities.

[0020] The dependency strength coefficient between adjacent confirmed associated vulnerabilities is determined based on the triggering time interval of adjacent confirmed associated vulnerabilities in the associated vulnerability chain.

[0021] The vulnerability chain risk value is calculated based on the trigger probability value and processing difficulty value of each confirmed associated vulnerability in the associated vulnerability chain, the chain risk bonus value, and the dependency strength coefficient between each adjacent confirmed associated vulnerability.

[0022] Optionally, based on the terminal's physical attribute data, a digital twin model is used to simulate the environment in which the enterprise intranet terminal is located and the changes in the terminal's operational status after the vulnerability is triggered, in order to generate an environmental risk coefficient, including:

[0023] Based on the physical attribute data of the terminals, a digital twin model is used to simulate the actual distribution scenario of the enterprise intranet terminals, so as to form a simulated environment scenario in which the enterprise intranet terminals are located.

[0024] The terminal device type and service life of the enterprise intranet terminal are associated with the corresponding area in the environmental simulation scenario to generate a real-time physical environment parameter sequence for each enterprise intranet terminal.

[0025] Based on the heat dissipation structure parameters, real-time physical environment parameter sequence, and corresponding hardware aging coefficient of each enterprise intranet terminal, the digital twin model is used to simulate the change process of the enterprise intranet terminal's operating status after the vulnerability is triggered, so as to generate simulation data.

[0026] Based on the simulation data and the deployment location information of the enterprise intranet terminals, the vulnerability propagation speed coefficient and the number of affected terminals are determined.

[0027] By integrating the simulated data with the vulnerability propagation rate coefficient and the number of associated terminals affected, an environmental risk coefficient is obtained for the impact of different physical environments on the vulnerability.

[0028] Optionally, based on the simulation data and the deployment location information of the enterprise intranet terminals, the vulnerability propagation speed coefficient and the number of affected terminals are determined, including:

[0029] Based on the physical coordinates of each enterprise intranet terminal in the deployment location information, the straight-line distance between the terminal that triggered the vulnerability and the terminal that did not trigger the vulnerability is calculated. Combined with the temperature exceedance peak in the simulation data, the distance influence weight is determined.

[0030] Based on the terminal network connection relationships in the deployment location information, determine the network connection tightness value;

[0031] Based on the distance influence weight and the network connection tightness value, the initial speed value of the vulnerability spreading from the terminal that triggered the vulnerability to the terminal that did not trigger the vulnerability is calculated. Combined with the minimum heat dissipation efficiency value in the simulation data, the initial speed value is adjusted to obtain the vulnerability spread speed coefficient.

[0032] Based on the vulnerability propagation speed coefficient, the vulnerability propagation range within a preset time period is determined. Target terminals within the vulnerability propagation range that have core business tags and are of the same type as the terminal that triggered the vulnerability are selected for confirmation. Target terminals that are already in a vulnerability-triggered state are excluded, forming a target terminal set. The number of target terminals in the target terminal set is counted as the number of associated terminal impacts.

[0033] Optionally, based on the real-time hardware resource data and the terminal physical attribute data, the load risk value corresponding to the enterprise intranet terminal is calculated, including:

[0034] Based on the real-time CPU utilization rate, real-time memory occupancy rate, and real-time disk read / write rate in the real-time hardware resource data, and combined with the maximum CPU load, total memory capacity, and maximum disk read / write rate in the terminal physical attribute data, the basic load rate of the enterprise intranet terminal is calculated. The basic load rate includes the processor load rate, memory load rate, and disk load rate.

[0035] Based on the business importance tags in the terminal physical attribute data, the business weight coefficient of the enterprise intranet terminal is determined, wherein the business weight coefficient of the enterprise intranet terminal with the core business tag is higher than the business weight coefficient of the enterprise intranet terminal with the ordinary business tag.

[0036] The business-related load rate is obtained by weighted summing of the basic load rate and business weight coefficient of the enterprise intranet terminals.

[0037] Based on the business-related load rate, hardware aging coefficient, and heat dissipation redundancy capability parameters in the terminal physical attribute data, a resource redundancy adjustment coefficient is determined. Combined with the business-related load rate, the load risk value corresponding to the enterprise intranet terminal is calculated.

[0038] Optionally, based on the vulnerability chain risk value, the environmental risk coefficient, and the load risk value, the vulnerability priority in the enterprise intranet terminal is assessed, including:

[0039] Based on the business importance tag in the terminal physical attribute data, determine the risk weight coefficients corresponding to the vulnerability chain risk value, the environmental risk coefficient, and the load risk value, respectively, so as to calculate the vulnerability chain risk contribution value, the environmental risk contribution value, and the load risk contribution value.

[0040] Based on the vulnerability remediation time of the corresponding vulnerability in the enterprise intranet terminal in the historical vulnerability assessment data, and combined with the vulnerability propagation speed coefficient, the urgency adjustment factor is determined.

[0041] Based on the vulnerability chain risk contribution value, environmental risk contribution value, and load risk contribution value, and combined with the urgency adjustment factor, the vulnerability priority score is calculated.

[0042] Based on the business importance tags of the enterprise intranet terminals, a risk tolerance threshold is set, and the vulnerability priority score is compared with the risk tolerance threshold to assess the vulnerability priority in the enterprise intranet terminals.

[0043] Secondly, this application provides a vulnerability prioritization assessment method and system based on a large language model, including:

[0044] The acquisition module is used to acquire real-time hardware resource data, historical vulnerability assessment data, and physical attribute data of the enterprise intranet terminals. The historical vulnerability assessment data includes the vulnerability trigger frequency and vulnerability repair time for different vulnerabilities.

[0045] The parsing module is used to parse the historical vulnerability assessment data using a large language model to identify the triggering dependencies between different vulnerabilities and generate vulnerability chain risk values ​​based on the triggering dependencies between different vulnerabilities.

[0046] The simulation module is used to simulate the environment of the enterprise intranet terminal and the changes in the operating status of the enterprise intranet terminal after the vulnerability is triggered, based on the terminal's physical attribute data and using a digital twin model, so as to generate an environmental risk coefficient.

[0047] The calculation module is used to calculate the load risk value corresponding to the enterprise intranet terminal based on the real-time hardware resource data and the terminal physical attribute data;

[0048] The assessment module is used to assess the vulnerability priority in the enterprise intranet terminal based on the vulnerability chain risk value, the environmental risk coefficient, and the load risk value.

[0049] Thirdly, this application provides an electronic device, comprising:

[0050] Memory, used to store computer programs;

[0051] A processor, used to implement the steps of a vulnerability prioritization method based on a large language model as described in the first aspect above, when executing the computer program.

[0052] Fourthly, this application provides a computer-readable storage medium storing a computer program that, when executed by a processor, can implement the steps of the vulnerability priority assessment method based on a large language model as described in the first aspect above.

[0053] The beneficial effects of this application are:

[0054] This application presents a vulnerability prioritization method based on a large language model. By acquiring real-time hardware resource data, historical vulnerability database assessment data, and terminal physical attribute data from enterprise intranet terminals, it comprehensively collects key multi-source information affecting vulnerability risk, providing a data foundation for dynamic assessment. It utilizes a large language model to parse historical assessment data to identify trigger dependencies between vulnerabilities and generate vulnerability chain risk values, overcoming the shortcomings of traditional methods in identifying implicit correlation logic and improving the modeling depth and semantic understanding of complex attack paths. Simultaneously, it combines digital twin technology to simulate the terminal's environment and its operational state changes after vulnerability triggering based on physical attribute data, achieving a refined restoration of the impact of real physical conditions and compensating for the coarse-grained deficiency of relying solely on network logical partitions for environmental assessment. Furthermore, it calculates load risk values ​​based on real-time hardware resources and physical attributes, enhancing the responsiveness to the terminal's current operational state. Finally, it integrates vulnerability chain risk values, environmental risk coefficients, and load risk values ​​for comprehensive prioritization, improving the accuracy and adaptability of vulnerability ranking in real-world business scenarios and supporting more scientific and fine-grained security decisions.

[0055] Furthermore, by constructing an environmental simulation scenario that includes typical areas such as open workstations and enclosed server rooms, and integrating dynamic change rules such as personnel density and heat dissipation system load, combined with terminal equipment type, service life, and heat dissipation structure parameters, a real-time physical environment parameter sequence reflecting actual operating conditions is generated. This drives the digital twin model to simulate the evolution of the terminal's operating state after a vulnerability is triggered, and generates an environmental risk coefficient accordingly. This achieves a leap from static logical partitioning to dynamic physical environment impact modeling, enhances the ability to characterize the differences in vulnerability behavior under different deployment environments, and also reflects the amplification effect of factors such as equipment aging and local temperature control failure on security risks, thereby improving the credibility and guiding value of the assessment results in complex real-world scenarios. It also strengthens the coupling relationship between risk assessment and actual operating conditions, making vulnerability priority ranking more reflective of the real threat propagation patterns. Attached Figure Description

[0056] To more clearly illustrate the technical solutions of the embodiments of this application or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments of this application. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0057] Figure 1 A flowchart illustrating a vulnerability priority assessment method based on a large language model, provided for an embodiment of this application;

[0058] Figure 2 A schematic diagram illustrating a specific implementation of a vulnerability priority assessment method based on a large language model, provided in this application embodiment;

[0059] Figure 3 This is a schematic diagram of the structure of a vulnerability priority assessment system based on a large language model, provided in an embodiment of this application. Detailed Implementation

[0060] Current vulnerability assessment methods based on graph structures and fixed rules struggle to fully understand the deep semantic relationships in vulnerability descriptions and have limited ability to identify implicit exploitation paths between cross-system components. Meanwhile, environmental risk modeling often remains at the network logic level, lacking dynamic characterization of the impact of real physical conditions such as temperature, humidity, and equipment layout. The assessment process often ignores the actual impact of terminal load fluctuations and hardware status changes on the attack surface, leading to a disconnect between risk assessment and on-site conditions, making it difficult to support accurate and adaptive vulnerability response strategies in complex business environments.

[0061] To enable those skilled in the art to better understand the present application, the present application will be further described in detail below with reference to the accompanying drawings and specific embodiments. Obviously, the described embodiments are merely some embodiments of the present application, and not all embodiments. Based on the embodiments in this application, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of this application.

[0062] The core of this application is to provide a vulnerability priority assessment method based on a large language model. A flowchart of one specific implementation method is shown below. Figure 1 As shown, the method includes:

[0063] Step 101: Obtain real-time hardware resource data, historical vulnerability assessment data, and physical attribute data of the enterprise intranet terminals. The historical vulnerability assessment data includes the vulnerability trigger frequency and vulnerability repair time for different vulnerabilities.

[0064] In this step, the enterprise intranet terminal refers to the computing device deployed on the enterprise's internal network for processing core business or general office business, including open workstation terminals and closed computer room terminals.

[0065] Real-time hardware resource data refers to the real-time collection of enterprise intranet terminal hardware operating status data, including real-time CPU utilization, real-time memory occupancy, and real-time disk read / write speed.

[0066] Historical vulnerability assessment data refers to past vulnerability assessment data stored in the vulnerability database, including the vulnerability trigger frequency and vulnerability remediation time for different vulnerabilities.

[0067] Terminal physical attribute data refers to the physical and associated attribute data of enterprise intranet terminals, including device model, heat dissipation structure parameters, device service life, business importance tag, deployment location information, and heat dissipation redundancy capability parameters.

[0068] In this embodiment of the application, real-time hardware resource data, historical vulnerability assessment data, and physical attribute data of the enterprise intranet terminal are obtained through the terminal real-time monitoring module, the vulnerability database storage system, and the terminal configuration record, respectively.

[0069] Step 102: Use a large language model to parse the historical vulnerability assessment data to identify the triggering dependencies between different vulnerabilities, and generate vulnerability chain risk values ​​based on the triggering dependencies between different vulnerabilities.

[0070] In this step, the triggering dependency relationship between different vulnerabilities refers to the relationship where, under the same device type, the effect of the previous vulnerability being triggered satisfies the triggering conditions of the subsequent vulnerability, and the time interval between the two triggering is within the normal chain range, and the subsequent vulnerability is easily triggered when the previous vulnerability has not been patched.

[0071] The vulnerability chain risk value refers to a numerical value that quantifies the overall risk of a related vulnerability chain.

[0072] Step 103: Based on the physical attribute data of the terminal, use a digital twin model to simulate the environment of the enterprise intranet terminal and the changes in the operating status of the enterprise intranet terminal after the vulnerability is triggered, so as to generate an environmental risk coefficient.

[0073] In this step, the environmental simulation scenario refers to a three-dimensional simulation scenario of the physical environment of the enterprise intranet terminal constructed using a digital twin model.

[0074] The environmental risk coefficient refers to a coefficient that quantifies the impact of the physical environment on vulnerabilities.

[0075] Step 104: Based on the real-time hardware resource data and the terminal physical attribute data, calculate the load risk value corresponding to the enterprise intranet terminal.

[0076] In this step, the load risk value refers to the numerical value that quantifies the impact of the terminal hardware load and its own attributes on the vulnerability risk.

[0077] Step 105: Based on the vulnerability chain risk value, the environmental risk coefficient, and the load risk value, assess the vulnerability priority in the enterprise intranet terminal.

[0078] In this step, vulnerability priority refers to the order in which vulnerabilities in the enterprise's internal network terminals are addressed.

[0079] This application integrates real-time terminal hardware resources, historical vulnerability behavior data, and physical attribute information to construct a multi-dimensional risk analysis foundation. Leveraging the deep semantic analysis capabilities of large language models for vulnerability text information, it uncovers potential vulnerability trigger dependencies in historical data, enhancing the ability to identify complex attack chains. By introducing digital twin technology, it establishes high-fidelity simulated scenarios based on the terminal deployment environment and device characteristics, dynamically predicting the evolution of the operational state under different physical conditions after vulnerability triggering, thus quantifying the impact of environmental factors on risk. Combining real-time load status to calculate operational risk weights, it ultimately integrates attack path risk, environmental impact level, and system load level for comprehensive evaluation, making vulnerability prioritization more closely aligned with actual threats in real business scenarios. It can identify implicit vulnerability trigger dependencies, avoiding limitations of manual features; multi-dimensional risk fusion combined with the characteristics of the vulnerability to be evaluated to assess priority improves the alignment with real threats, providing support for scenario-based and refined vulnerability handling.

[0080] This application provides a specific embodiment. Step 102 involves using a large language model to parse the historical vulnerability assessment data to identify the triggering dependencies between different vulnerabilities. This specifically includes the following steps:

[0081] Step 201: Using a large language model, extract the triggering conditions, impact results, and target terminal device types associated with each vulnerability from the historical vulnerability assessment data.

[0082] In this step, the trigger condition information refers to the prerequisite conditions that must be met for each vulnerability to be triggered.

[0083] Impact information refers to the specific consequences on the hardware status, software functions, or system security of enterprise intranet terminals after the vulnerability is triggered.

[0084] The target terminal device type refers to the specific device category of the enterprise intranet terminals that the vulnerability can affect.

[0085] In this embodiment of the application, the vulnerability description text, trigger records and other information contained in the vulnerability history assessment data are input into the big language model. Through the semantic understanding capability of the big language model, the triggering condition information, the impact result information after the vulnerability is triggered, and the target terminal device type associated with each vulnerability are identified and extracted.

[0086] Step 202: Perform correlation matching on the triggering conditions, impact results, and target terminal device types of each vulnerability to identify potential trigger-related vulnerabilities that belong to the same device type and have a connection between the triggering conditions and impact results.

[0087] In this step, the connection between the triggering condition information and the impact result information means that the impact result information of a certain vulnerability happens to match the triggering condition information of another vulnerability, so that the consequences of the former vulnerability being triggered can directly satisfy the triggering prerequisite of the latter vulnerability.

[0088] Potential trigger-related vulnerabilities refer to a group of vulnerabilities that belong to the same target terminal device type and whose triggering conditions and impact results are interconnected.

[0089] In this embodiment, all vulnerabilities are classified according to the type of target terminal device, and a set of vulnerabilities belonging to the same type of target terminal device is selected. Then, within this set, the triggering condition information of a vulnerability is compared with the impact result information of other vulnerabilities. If the impact result information of a certain vulnerability satisfies the triggering condition information of another vulnerability, it is determined that there is a connection between the triggering condition information and the impact result information of the two vulnerabilities, and these two or more vulnerabilities with such a connection are marked as potential trigger-related vulnerabilities.

[0090] Step 203: Extract the vulnerability trigger time sequence and vulnerability remediation completion time information corresponding to the potential trigger-related vulnerabilities from the vulnerability history assessment data.

[0091] In this embodiment of the application, time-related data corresponding to each potential triggering vulnerability is retrieved and extracted from historical vulnerability assessment data. Specifically, the vulnerability trigger time sequence refers to the specific time of each past trigger of the vulnerability, recorded chronologically; the vulnerability fix completion time information refers to the specific time point from the start of fix application to its completion after each past discovery of the vulnerability.

[0092] Step 204: Based on the vulnerability triggering time sequence and vulnerability remediation completion time information, verify the potential triggering associated vulnerabilities to determine the triggering dependency relationship between different vulnerabilities. The verification operation includes comparing the historical triggering time of the first vulnerability with the historical triggering time of the second vulnerability in the potential triggering associated vulnerabilities, comparing the vulnerability remediation completion time of the first vulnerability with the historical triggering time of the second vulnerability, and determining whether the triggering time interval between the first vulnerability and the second vulnerability is within the time range of conventional vulnerability chain triggering. The first vulnerability and the second vulnerability are any different vulnerabilities in the potential triggering associated vulnerabilities.

[0093] In this step, the first vulnerability refers to a vulnerability arbitrarily selected from potential trigger-related vulnerabilities that serves as a preceding trigger in the trigger dependency relationship.

[0094] Historical trigger time refers to the specific time when a vulnerability was triggered each time it was used in the past.

[0095] The second vulnerability refers to the vulnerability selected from potential trigger-related vulnerabilities as a subsequent trigger in the trigger dependency relationship, corresponding to the first vulnerability.

[0096] The time range of conventional vulnerability chain triggering refers to the common time interval between the triggering of a preceding vulnerability and the triggering of a subsequent vulnerability, which is determined by statistics from a large number of vulnerability chain triggering cases in the industry.

[0097] In this embodiment, two different vulnerabilities are first randomly selected from the potential trigger-related vulnerabilities and designated as the first vulnerability and the second vulnerability, respectively. Then, the historical trigger times of the first and second vulnerabilities are extracted from the vulnerability trigger time sequence, and the vulnerability remediation completion time of the first vulnerability is extracted from the vulnerability remediation completion time information. Subsequently, the historical trigger times of the first and second vulnerabilities are compared to determine whether the second vulnerability occurred after the first vulnerability was triggered. Finally, the vulnerability remediation completion time of the first vulnerability is compared to the historical trigger time of the second vulnerability to determine whether the second vulnerability occurred before the first vulnerability was remediated.

[0098] Finally, the triggering time interval between the first and second vulnerabilities is calculated to determine whether this interval falls within the time range of typical vulnerability chain triggering based on statistics from a large number of vulnerability chain triggering cases in the industry. If the above comparison and judgment results are satisfied, it is determined that there is a triggering dependency relationship between the first and second vulnerabilities, and then the triggering dependency relationship between different vulnerabilities among all potential triggering related vulnerabilities is determined.

[0099] This application's embodiments improve the efficiency and accuracy of information extraction through a large language model, enabling the identification of hard-to-detect hidden triggering associations and enhancing the accuracy and dynamic adaptability of vulnerability dependency identification.

[0100] This application provides a specific embodiment. Step 102, based on the triggering dependency relationship between the different vulnerabilities, generates a vulnerability chain risk value, which specifically includes the following steps:

[0101] Step 201: Based on the triggering dependency relationship between the different vulnerabilities, vulnerabilities with triggering dependency relationships are identified as confirmed associated vulnerabilities, and the confirmed associated vulnerabilities are connected to form an associated vulnerability chain.

[0102] In this step, triggering dependency refers to the logical association that, once verified, triggering a previous vulnerability can lead to a subsequent vulnerability.

[0103] Identifying associated vulnerabilities refers to vulnerabilities that have a triggering dependency relationship and is the basic unit that constitutes an associated vulnerability chain.

[0104] A chain of associated vulnerabilities refers to a logical chain formed by connecting confirmed related vulnerabilities in the order of their trigger dependencies.

[0105] In this embodiment, based on the triggering dependency relationship between different vulnerabilities, vulnerabilities with such a triggering dependency relationship are selected from all vulnerabilities and marked as confirmed associated vulnerabilities. Then, according to the dependency order in which the triggering of the previous vulnerability can trigger the subsequent vulnerability, the confirmed associated vulnerabilities are connected sequentially. For example, if the triggering of the first vulnerability can trigger the second vulnerability, then the first vulnerability and the second vulnerability are connected adjacently to form an associated vulnerability chain containing multiple confirmed associated vulnerabilities and having triggering logic.

[0106] Step 202: Based on the vulnerability triggering frequency and vulnerability repair time corresponding to each confirmed associated vulnerability in the associated vulnerability chain, determine the triggering probability value and processing difficulty value of each confirmed associated vulnerability.

[0107] In this embodiment, firstly, for each confirmed associated vulnerability in the associated vulnerability chain, its corresponding vulnerability trigger frequency and vulnerability remediation time are retrieved from the historical vulnerability assessment data. The vulnerability trigger frequency of each confirmed associated vulnerability is divided by the total duration of the period to obtain the trigger probability value of the vulnerability; the processing difficulty value is determined based on the length of vulnerability remediation time, wherein the longer the remediation time, the higher the processing difficulty value, thereby matching a corresponding trigger probability value and processing difficulty value for each confirmed associated vulnerability.

[0108] Step 203: Count the total number of vulnerabilities in the associated vulnerability chain, and determine the chain risk bonus value based on the total number of vulnerabilities.

[0109] In this step, the cascading risk bonus value refers to a numerical value determined based on the total number of vulnerabilities, used to amplify the additional risks caused by the cascading triggering of vulnerabilities.

[0110] In this embodiment, the total number of vulnerabilities is obtained by counting the number of associated vulnerabilities in the previously formed vulnerability chain. Then, according to the preset rule corresponding to the total number of vulnerabilities and the chain risk bonus value, such as the higher the total number of vulnerabilities, the wider the scope of vulnerability chain triggering, and the higher the corresponding chain risk bonus value, the chain risk bonus value corresponding to the associated vulnerability chain is determined.

[0111] Step 204: Determine the dependency strength coefficient between adjacent confirmed associated vulnerabilities based on the triggering time interval of adjacent confirmed associated vulnerabilities in the associated vulnerability chain.

[0112] In this step, adjacent confirmation-related vulnerabilities refer to two confirmation-related vulnerabilities in a chain of related vulnerabilities that are logically connected in their triggering, such as the latter vulnerability that can be directly triggered after the former vulnerability is triggered.

[0113] The dependency strength coefficient is a numerical value that quantifies the degree of impact between adjacent confirmed related vulnerabilities.

[0114] In this embodiment, adjacent confirmed associated vulnerabilities in the associated vulnerability chain are clearly identified. The trigger times of adjacent confirmed associated vulnerabilities are extracted from the vulnerability trigger time sequence, and the trigger time interval between them is calculated, which is the trigger time of the latter vulnerability minus the trigger time of the former vulnerability. Then, according to the rule corresponding to the trigger time interval and the dependency strength coefficient, that is, the shorter the interval, the stronger the impact of the former vulnerability on the triggering of the latter vulnerability, and the higher the dependency strength coefficient, the dependency strength coefficient between each pair of adjacent confirmed associated vulnerabilities is determined.

[0115] Step 205: Calculate the vulnerability chain risk value based on the trigger probability value and processing difficulty value of each confirmed associated vulnerability in the associated vulnerability chain, the chain risk bonus value, and the dependency strength coefficient between each adjacent confirmed associated vulnerability.

[0116] In this embodiment, the trigger probability value of each confirmed associated vulnerability in the associated vulnerability chain is multiplied by the processing difficulty value, and all results are added together to obtain the basic risk sum. Then, this basic risk sum is added to the chain risk bonus value determined in the previous step to obtain the intermediate risk value. Subsequently, the average value of the dependency strength coefficients between all adjacent confirmed associated vulnerabilities is calculated, and this value is multiplied by the intermediate risk value to obtain the vulnerability chain risk value corresponding to the associated vulnerability chain.

[0117] The embodiments of this application improve the accuracy and comprehensiveness of vulnerability chain risk assessment, providing a reliable basis for subsequent priority assessment.

[0118] This application provides a specific embodiment. Step 103 involves using a digital twin model to simulate the environment of the enterprise intranet terminal based on the terminal's physical attribute data, as well as the changes in the terminal's operating status after the vulnerability is triggered, to generate an environmental risk coefficient. This specifically includes the following steps:

[0119] Step 301: Based on the terminal physical attribute data, use a digital twin model to simulate the actual distribution scenario of the enterprise intranet terminals, so as to form an environmental simulation scenario in which the enterprise intranet terminals are located.

[0120] In this step, the actual distribution scenario refers to the placement and regional distribution of enterprise intranet terminals in the real physical space, which is reconstructed using a digital twin model based on the terminal's physical attribute data.

[0121] An environment simulation scenario refers to a simulation scenario that is based on the actual distribution of terminals, restores the real physical space layout, and allows for subsequent configuration of environmental parameters.

[0122] In this embodiment, the deployment location, device type, and number of enterprise intranet terminals are first extracted from the terminal physical attribute data. This information is then imported into a digital twin model to recreate the placement of terminals in a real physical space at a 1:1 scale. For example, ordinary office terminals are arranged in an open area with a 2-meter interval between workstations, while core terminals are deployed in a closed area in cabinet layers. This constructs an initial simulated scenario that clearly reflects the actual spatial layout of the enterprise intranet terminals.

[0123] Then, environmental parameters are configured in the initial simulation scenario to form an optimized environmental simulation scenario. The specific process includes: for the open workstation area in the initial simulation scenario, the initial temperature and humidity are set with reference to air quality standards, and the air circulation rate is calculated according to the normal ventilation frequency; for the enclosed computer room area, the initial constant temperature is set according to the relevant design specifications of the data center, and the rated power of the heat dissipation system is calculated according to the total power consumption of the core terminals; at the same time, preset dynamic change rules are added. For example, one dynamic change rule can be: for the open workstation area, the temperature and humidity fluctuation range is set according to the personnel density change, where the temperature and humidity fluctuate positively when the personnel density increases and fluctuate negatively when the personnel density decreases; for the enclosed computer room area, the power adjustment threshold is set according to the heat dissipation system load change, where the heat dissipation power is automatically adjusted when the heat dissipation system load reaches the power adjustment threshold, and finally the environmental simulation scenario is formed.

[0124] Step 302: Associate the terminal device type and device service life of the enterprise intranet terminal with the corresponding area in the environmental simulation scenario to generate a real-time physical environment parameter sequence for each enterprise intranet terminal.

[0125] In this step, the terminal device type refers to the category of enterprise intranet terminals according to their function or purpose. This terminal device type includes industrial control terminals, general office terminals, and financial transaction terminals.

[0126] The corresponding area refers to the physical area in the optimized simulation scenario that is compatible with the type of terminal device.

[0127] The real-time physical environment parameter sequence refers to the dynamic set of physical environment parameters of each enterprise intranet terminal recorded in chronological order. This parameter sequence includes hourly temperature and humidity, air circulation rate, and heat dissipation system power.

[0128] In this embodiment, the corresponding area is matched according to the type of terminal device. For example, one matching method is: core industrial terminals and financial transaction terminals correspond to closed computer room areas, and ordinary office terminals correspond to open workstation areas. Then, the parameter benchmark is adjusted in combination with the service life of the equipment. For example, one adjustment method is: for terminals with a longer service life, the initial value of real-time physical environment parameters is appropriately higher than that of newer terminals. Finally, data is collected at a preset frequency, and combined with the dynamic change rules of the corresponding area, a real-time physical environment parameter sequence of each terminal, such as temperature and humidity, air circulation rate, and heat dissipation system power, is generated in time order.

[0129] Step 303: Based on the heat dissipation structure parameters, real-time physical environment parameter sequence, and corresponding hardware aging coefficient of each enterprise intranet terminal, simulate the change process of the enterprise intranet terminal's operating status after the vulnerability is triggered using a digital twin model to generate simulation data.

[0130] In this step, the hardware aging factor refers to the numerical value that quantifies the degree of hardware performance degradation caused by the increasing usage time of enterprise intranet terminals.

[0131] Simulated data refers to the recorded data showing the changes in the hardware operating status of enterprise intranet terminals over time after a vulnerability is triggered, simulated using a digital twin model.

[0132] In this embodiment, the heat dissipation structure parameters of each terminal are first extracted from the terminal physical attribute data. Then, the hardware aging coefficient is determined based on the device's service life in the terminal physical attribute data. For example, the coefficient is 0.5 for less than 1 year, 0.7 for 1-3 years, and 0.9 for more than 3 years. This embodiment does not specifically limit this. Finally, the heat dissipation structure parameters, real-time physical environment parameter sequence, and hardware aging coefficient are input into the digital twin model to simulate the changes in power consumption, temperature fluctuations, and heat dissipation efficiency decay of the enterprise intranet terminals after the vulnerability is triggered. The temperature and heat dissipation efficiency at each time point are recorded to generate simulation data.

[0133] Step 304: Based on the simulation data and the deployment location information of the enterprise intranet terminals, determine the vulnerability propagation speed coefficient and the number of affected terminals.

[0134] In this step, the vulnerability propagation rate coefficient refers to a numerical value that quantifies how quickly a vulnerability spreads from the endpoint that triggered the vulnerability to other non-thrown endpoints.

[0135] The number of affected associated terminals refers to the total number of enterprise intranet terminals that may be affected by the currently triggered vulnerability within the scope of the vulnerability's spread.

[0136] Step 305: Integrate the simulation data with the vulnerability propagation speed coefficient and the number of associated terminals to obtain the environmental risk coefficient of the impact of different physical environments on the vulnerability.

[0137] In this embodiment, the duration of temperature exceeding the standard and the time points of low heat dissipation are first extracted from the simulation data. The duration of temperature exceeding the standard is the total duration of temperature exceeding the normal range, and the time points of low heat dissipation are the time points where heat dissipation efficiency is lower than a preset threshold. These two parameters, along with the vulnerability propagation speed coefficient and the number of affected associated terminals, are then normalized to eliminate the impact of differences in unit and numerical range of different parameters. Finally, corresponding weights are assigned according to the contribution of each parameter to the risk, and the normalized values ​​of each parameter are weighted and summed to obtain an environmental risk coefficient that quantifies the impact of different physical environments on the vulnerability.

[0138] Optional, step 304, such as Figure 2 As shown, based on the simulation data and the deployment location information of the enterprise intranet terminals, the vulnerability propagation speed coefficient and the number of affected terminals are determined, specifically including the following steps:

[0139] Step 311: Based on the physical coordinates of each enterprise intranet terminal in the deployment location information, calculate the straight-line distance between the terminal that triggered the vulnerability and the terminal that did not trigger the vulnerability, and determine the distance influence weight by combining the temperature exceedance peak in the simulation data.

[0140] In this step, the physical coordinates of each enterprise intranet terminal refer to the X-axis, Y-axis, or three-dimensional coordinate data used to identify the specific location of each terminal in the real physical space.

[0141] A vulnerability-triggered endpoint refers to an endpoint within the enterprise's internal network where a vulnerability has been triggered.

[0142] Non-triggered vulnerability endpoints refer to endpoints within the enterprise intranet that have not yet been triggered by vulnerabilities, reflecting the objects that may be affected by the spread of vulnerabilities.

[0143] The peak temperature exceeding the limit refers to the maximum value in the simulation data where the terminal temperature exceeds the normal operating temperature range after the vulnerability is triggered.

[0144] The distance influence weight refers to the numerical value of the straight-line distance between the terminal that triggered the vulnerability and the terminal that did not trigger the vulnerability on the degree of impact of the vulnerability spread, reflecting the influence of spatial distance on the spread of the vulnerability.

[0145] Step 312: Determine the network connection tightness value based on the terminal network connection relationship in the deployment location information.

[0146] In this step, the terminal network connection relationship refers to the network topology association between terminals in the enterprise intranet, such as whether they belong to the same subnet, whether there is a direct data interaction link, and the frequency of data interaction.

[0147] The network connectivity strength value refers to a numerical value that quantifies the degree of network connection between the terminal that triggered the vulnerability and the terminal that did not trigger the vulnerability.

[0148] Step 313: Based on the distance influence weight and the network connection tightness value, calculate the initial speed value of the vulnerability spreading from the terminal that triggered the vulnerability to the terminal that did not trigger the vulnerability. Combine the minimum heat dissipation efficiency value in the simulation data to adjust the initial speed value and obtain the vulnerability spread speed coefficient.

[0149] In this step, the initial velocity value refers to the base velocity value of the vulnerability spreading from the terminal that triggered the vulnerability to the terminal that did not take into account the terminal's heat dissipation efficiency.

[0150] Step 314: Based on the vulnerability propagation speed coefficient, determine the vulnerability propagation range within a preset time period, filter out the target terminals to be confirmed that are within the vulnerability propagation range and have core business tags and are of the same type as the terminal that triggered the vulnerability, and exclude the target terminals to be confirmed that are already in the vulnerability triggering state, forming a target terminal set, and count the number of target terminals in the target terminal set as the number of associated terminal impacts.

[0151] In this step, the vulnerability propagation range refers to the physical space area that the vulnerability may spread and cover from the terminal that triggered the vulnerability within a preset time period.

[0152] The core business label refers to a tag used to identify whether an enterprise's intranet terminal carries core business.

[0153] The target terminal to be confirmed refers to an enterprise intranet terminal that is within the scope of the vulnerability's spread and is of the same type as the terminal that triggered the vulnerability.

[0154] Vulnerability trigger status refers to whether a vulnerability has been triggered on an enterprise's internal network terminal.

[0155] The target terminal set refers to the set of terminals that may be affected by the vulnerability after excluding terminals that are already in a vulnerable state from the target terminals to be confirmed.

[0156] The target terminal refers to a single terminal in the target terminal set, that is, a terminal that has not been triggered within the scope of the vulnerability's spread, has the same type as the triggered terminal, and carries the core business tag.

[0157] In this embodiment, step 305 is implemented by specifically executing steps 311 to 314. Specifically: Step 311 involves extracting the physical coordinates of each enterprise intranet terminal from the deployment location information, including the coordinates of the core terminal that triggered the vulnerability and the coordinates of the non-triggered core terminal, and calculating the straight-line distance using the distance formula between two points. Then, the peak temperature exceeding the standard is extracted from the simulation data, and the weight of the distance influence is determined according to the rule that the closer the straight-line distance and the higher the peak temperature exceeding the standard, the greater the weight. Step 312 involves extracting the terminal network connection relationship from the deployment location information, such as whether the triggered and non-triggered terminals belong to the same subnet, have a direct data interaction link, and have a data interaction frequency, and determining the network connection tightness value according to the rule that the closer the association, the higher the value.

[0158] Continue with step 313 and calculate: Initial speed value = Distance influence weight × Network connection tightness value; extract the minimum heat dissipation efficiency value from the simulation data and adjust it as follows: Vulnerability propagation speed coefficient = Initial speed value × Minimum heat dissipation efficiency value. Execute step 314, first set a preset time period, then calculate the vulnerability propagation range: Vulnerability propagation range = Vulnerability propagation speed coefficient × Preset time period. Filter out unconfirmed target terminals within this range that have core business tags and are consistent with the terminal type that triggered the vulnerability, exclude terminals that are already in a vulnerability-triggered state, form a target terminal set, count the number of target terminals in this set, and obtain the number of associated terminal impacts.

[0159] This application's embodiments break through the limitations of traditional methods that rely solely on network logical partitioning to assess environmental risks, fully reflecting the dynamic impact of the physical environment on vulnerabilities and improving the scenario-based and accurate nature of environmental risk assessment.

[0160] This application provides a specific embodiment. Step 104, based on the real-time hardware resource data and the terminal physical attribute data, calculates the load risk value corresponding to the enterprise intranet terminal, specifically including the following steps:

[0161] Step 401: Based on the real-time CPU utilization rate, real-time memory occupancy rate, and real-time disk read / write rate in the real-time hardware resource data, and combined with the maximum CPU load, total memory capacity, and maximum disk read / write rate in the terminal physical attribute data, calculate the basic load rate of the enterprise intranet terminal. The basic load rate includes the processor load rate, memory load rate, and disk load rate.

[0162] In this step, the base load rate refers to the quantitative value of the basic operating load of the enterprise's intranet terminal hardware, which is composed of the processor load rate, memory load rate, and disk load rate.

[0163] In this embodiment, the real-time CPU utilization rate, real-time memory occupancy rate, and real-time disk read / write speed of the enterprise intranet terminal are extracted from real-time hardware resource data. Then, the maximum CPU load, total memory capacity, and maximum disk read / write speed of the terminal are extracted from the terminal's physical attribute data. The load rates are calculated as follows: CPU load rate = CPU real-time utilization rate ÷ CPU maximum load; Memory load rate = Memory real-time occupancy rate ÷ Total memory capacity; Disk load rate = Disk real-time read / write speed ÷ Disk maximum read / write speed. These three load rates constitute the basic load rate of the enterprise intranet terminal.

[0164] Step 402: Determine the business weight coefficient of the enterprise intranet terminal based on the business importance tag in the terminal physical attribute data, wherein the business weight coefficient of the enterprise intranet terminal with the core business tag is higher than the business weight coefficient of the enterprise intranet terminal with the ordinary business tag.

[0165] In this step, the business importance label refers to the mark used to identify the importance of the business carried by the enterprise's intranet terminal, and it is divided into core business label and ordinary business label.

[0166] The business weight coefficient is a numerical value that quantifies the impact of the importance of enterprise intranet terminal services on load risk.

[0167] Ordinary business tags refer to a subcategory of business importance tags, corresponding to enterprise intranet terminals that carry non-critical business such as daily office work and file transfer.

[0168] In this embodiment, business importance tags for enterprise intranet terminals are extracted from terminal physical attribute data. These tags include core business tags and ordinary business tags. Then, a business weight coefficient is determined based on the tag type: enterprise intranet terminals with core business tags have a higher business weight coefficient than those with ordinary business tags. This distinguishes the load risk priority of different business terminals, ensuring that the load risk of critical business terminals is given priority consideration.

[0169] Step 403: The basic load rate and business weight coefficient of the enterprise intranet terminal are weighted and summed to obtain the business-related load rate.

[0170] In this step, the business-related load rate refers to the quantified value of terminal load that combines business importance, reflecting the correlation risk between terminal hardware load and business value, and is used to calculate the load risk value in subsequent calculations.

[0171] In this embodiment, the business weight coefficient and the basic load rate are obtained, and then weighted and summed according to a preset rule: the processor load rate, memory load rate, and disk load rate are multiplied by the business weight coefficient respectively to obtain three weighted sub-load rates. These three sub-load rates are then summed to obtain the business-related load rate, which reflects the impact of business importance on load, thus linking load assessment with the business value of the terminal.

[0172] Step 404: Determine the resource redundancy adjustment coefficient based on the service-related load rate, hardware aging coefficient, and heat dissipation redundancy capability parameters in the terminal physical attribute data. Combined with the service-related load rate, calculate the load risk value corresponding to the enterprise intranet terminal.

[0173] In this step, the heat dissipation redundancy capability parameter refers to the quantitative indicator of the remaining heat dissipation capability of the enterprise intranet terminal heat dissipation system. It is determined based on the heat dissipation hardware configuration in the terminal physical attribute data and reflects the heat dissipation redundancy space of the terminal when the load increases.

[0174] The resource redundancy adjustment coefficient is a numerical value that quantifies the redundancy capability of an enterprise's intranet terminals to cope with load fluctuations, reflecting the terminal's load risk buffering capability.

[0175] In this embodiment, a resource redundancy adjustment coefficient is determined based on the service-related load rate, hardware aging coefficient, and heat dissipation redundancy capability parameter in the terminal's physical attribute data: the higher the service-related load rate, the higher the hardware aging coefficient, and the lower the heat dissipation redundancy capability parameter, the lower the resource redundancy adjustment coefficient. Finally, the service-related load rate is multiplied by the resource redundancy adjustment coefficient to obtain the load risk value corresponding to the enterprise intranet terminal.

[0176] The embodiments of this application take into account hardware status, business attributes, and terminal aging, avoiding the one-sidedness of traditional methods that only consider hardware load, and improving the scenario adaptability and accuracy of load risk assessment.

[0177] This application provides a specific embodiment. Step 105 involves assessing the vulnerability priority in the enterprise intranet terminal based on the vulnerability chain risk value, the environmental risk coefficient, and the load risk value. This specifically includes the following steps:

[0178] Step 501: Based on the business importance tag in the terminal physical attribute data, determine the risk weight coefficients corresponding to the vulnerability chain risk value, the environmental risk coefficient, and the load risk value, respectively, so as to calculate the vulnerability chain risk contribution value, the environmental risk contribution value, and the load risk contribution value.

[0179] In this step, the risk weight coefficient refers to the numerical value that quantifies the impact of vulnerability chain risk value, environmental risk coefficient, and load risk value on vulnerability priority assessment.

[0180] The vulnerability chain risk contribution value, environmental risk contribution value, and load risk contribution value refer to the actual numerical values ​​of the vulnerability chain risk value, environmental risk coefficient, and load risk value in vulnerability priority assessment, respectively.

[0181] In this embodiment, the business importance tag of the enterprise intranet terminal is first extracted from the terminal physical attribute data. Based on the type of business importance tag, the risk weight coefficients corresponding to the vulnerability chain risk value, environmental risk coefficient, and load risk value are determined: For terminals with a core business tag, the risk weight coefficient corresponding to the vulnerability chain risk value is higher than that for terminals with ordinary business tags because the vulnerability has a greater impact on core business. For terminals with a closed data center deployment tag, the environmental risk has a more significant impact on the vulnerability, and the risk weight coefficient corresponding to the environmental risk coefficient is higher than that for terminals in open workstation areas.

[0182] The vulnerability chain risk value is then multiplied by its corresponding risk weight coefficient to obtain the vulnerability chain risk contribution value. The environmental risk coefficient is then multiplied by its corresponding risk weight coefficient to obtain the environmental risk contribution value. Finally, the load risk value is multiplied by its corresponding risk weight coefficient to obtain the load risk contribution value.

[0183] Step 502: Based on the vulnerability remediation time of the corresponding vulnerability in the enterprise intranet terminal in the vulnerability historical assessment data, and combined with the vulnerability propagation speed coefficient, determine the urgency adjustment factor.

[0184] In this step, the vulnerability to be assessed refers to a specific vulnerability in an enterprise intranet endpoint that requires priority assessment for handling. The urgency adjustment factor is a numerical value that quantifies the urgency requirement for handling the vulnerability to be assessed.

[0185] In this embodiment of the application, the vulnerability repair time of the vulnerability to be evaluated in the corresponding enterprise intranet terminal is retrieved and extracted from the vulnerability historical assessment data. Combined with the vulnerability propagation speed coefficient corresponding to the vulnerability to be evaluated, the urgency adjustment factor is determined: the shorter the vulnerability repair time and the higher the vulnerability propagation speed coefficient of the vulnerability to be evaluated, the larger the corresponding urgency adjustment factor, and vice versa.

[0186] Step 503: Calculate the vulnerability priority score based on the vulnerability chain risk contribution value, environmental risk contribution value, and load risk contribution value, combined with the urgency adjustment factor.

[0187] In this step, the vulnerability priority score refers to a specific numerical value that quantifies the priority of the vulnerability to be evaluated.

[0188] In this embodiment, the vulnerability chain risk contribution value, environmental risk contribution value, and load risk contribution value are added together to obtain the basic vulnerability priority score. Then, the basic vulnerability priority score is multiplied by an urgency adjustment factor. This urgency adjustment factor amplifies the priority score of high-urgency vulnerabilities, ultimately yielding a vulnerability priority score that reflects the urgency of the vulnerability.

[0189] Step 504: Based on the business importance tags of the enterprise intranet terminals, set a risk tolerance threshold, and compare the vulnerability priority score with the risk tolerance threshold to assess the vulnerability priority in the enterprise intranet terminals.

[0190] In this step, the risk tolerance threshold refers to the critical value set by the enterprise based on the importance of the end-user business to determine whether a vulnerability needs to be addressed with high priority.

[0191] In this embodiment of the application, a risk tolerance threshold is set according to the business importance label of the enterprise intranet terminal: the risk tolerance threshold set for the terminal with the core business label is lower than that for the terminal with the ordinary business label because the core business has a low risk tolerance.

[0192] The vulnerability priority score obtained in the third step is then compared with the risk tolerance threshold corresponding to the terminal: if the vulnerability priority score is higher than the risk tolerance threshold, the vulnerability to be evaluated is determined to be high priority; if the vulnerability priority score is equal to the risk tolerance threshold, it is determined to be medium priority; if the vulnerability priority score is lower than the risk tolerance threshold, it is determined to be low priority, thus completing the assessment of vulnerability priority in the enterprise intranet terminal.

[0193] The embodiments of this application take into account risk dimensions, urgency, and business attributes, improve the accuracy of vulnerability priority assessment and scenario adaptability, and provide a scientific basis for refined vulnerability handling.

[0194] Figure 3 This application provides a schematic diagram illustrating a specific implementation of a vulnerability prioritization system based on a large language model, as shown in the following embodiments. Figure 3 The system may include:

[0195] The acquisition module 21 is used to acquire real-time hardware resource data, historical vulnerability assessment data and physical attribute data of the enterprise intranet terminal. The historical vulnerability assessment data includes the vulnerability triggering frequency and vulnerability repair time of different vulnerabilities.

[0196] The parsing module 22 is used to parse the historical vulnerability assessment data using a large language model to identify the triggering dependencies between different vulnerabilities and generate vulnerability chain risk values ​​based on the triggering dependencies between different vulnerabilities.

[0197] The simulation module 23 is used to simulate the environment of the enterprise intranet terminal and the change in the operating status of the enterprise intranet terminal after the vulnerability is triggered, based on the terminal's physical attribute data and using a digital twin model, so as to generate an environmental risk coefficient.

[0198] Calculation module 24 is used to calculate the load risk value corresponding to the enterprise intranet terminal based on the real-time hardware resource data and the terminal physical attribute data;

[0199] The evaluation module 25 is used to evaluate the vulnerability priority in the enterprise intranet terminal based on the vulnerability chain risk value, the environmental risk coefficient, and the load risk value.

[0200] This application provides a vulnerability priority assessment system based on a large language model to implement the aforementioned vulnerability priority assessment method based on a large language model. Therefore, the specific implementation of the vulnerability priority assessment system based on a large language model can be found in the embodiment section of the vulnerability priority assessment method based on a large language model mentioned above. The specific implementation can be referred to the description of the corresponding embodiments, which will not be repeated here.

[0201] This application also provides an electronic device, comprising: a memory for storing a computer program; and a processor for executing the computer program to implement the steps of any of the above-described vulnerability priority assessment methods based on a large language model.

[0202] This application also provides a computer-readable storage medium storing a computer program, which, when executed by a processor, implements the steps of any of the above-described vulnerability priority assessment methods based on a large language model.

[0203] In one exemplary embodiment, the aforementioned computer-readable storage medium may include, but is not limited to, various media capable of storing computer programs, such as USB flash drives, read-only memory, random access memory, portable hard drives, magnetic disks, or optical disks.

[0204] Embodiments of this application also provide a computer program product, which includes a computer program that, when executed by a processor, implements the steps in any of the above embodiments of the vulnerability priority assessment method based on a large language model.

[0205] Those skilled in the art will further recognize that the units and algorithm steps of the various examples described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, computer software, or a combination of both. To clearly illustrate the interchangeability of hardware and software, the components and steps of the various examples have been generally described in terms of functionality in the foregoing description. Whether these functions are implemented in hardware or software depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of this application.

[0206] The above provides a detailed description of the vulnerability priority assessment method and system based on a large language model provided in this application. Specific examples have been used to illustrate the principles and implementation methods of this application. The descriptions of the embodiments above are only for the purpose of helping to understand the method and its core ideas. It should be noted that those skilled in the art can make several improvements and modifications to this application without departing from the principles of this application, and these improvements and modifications also fall within the protection scope of this application.

Claims

1. A vulnerability priority assessment method based on a large language model, characterized in that, include: Acquire real-time hardware resource data, historical vulnerability assessment data, and physical attribute data of enterprise intranet terminals. The historical vulnerability assessment data includes the vulnerability trigger frequency and vulnerability repair time for different vulnerabilities. The historical vulnerability assessment data is analyzed using a large language model to identify the triggering dependencies between different vulnerabilities, and a vulnerability chain risk value is generated based on the triggering dependencies between the different vulnerabilities. Based on the physical attribute data of the terminal, a digital twin model is used to simulate the environment of the enterprise intranet terminal and the change process of the terminal's operating status after the vulnerability is triggered, so as to generate an environmental risk coefficient. Based on the real-time hardware resource data and the terminal physical attribute data, calculate the load risk value corresponding to the enterprise intranet terminal; Based on the vulnerability chain risk value, the environmental risk coefficient, and the load risk value, assess the vulnerability priority in the enterprise intranet terminal; Based on the terminal's physical attribute data, a digital twin model is used to simulate the environment in which the enterprise intranet terminal is located and the changes in the terminal's operational status after a vulnerability is triggered, in order to generate an environmental risk coefficient, including: Based on the physical attribute data of the terminals, a digital twin model is used to simulate the actual distribution scenario of the enterprise intranet terminals, so as to form a simulated environment scenario in which the enterprise intranet terminals are located. The terminal device type and service life of the enterprise intranet terminal are associated with the corresponding area in the environmental simulation scenario to generate a real-time physical environment parameter sequence for each enterprise intranet terminal. Based on the heat dissipation structure parameters, real-time physical environment parameter sequence, and corresponding hardware aging coefficient of each enterprise intranet terminal, the digital twin model is used to simulate the change process of the enterprise intranet terminal's operating status after the vulnerability is triggered, so as to generate simulation data. Based on the simulation data and the deployment location information of the enterprise intranet terminals, the vulnerability propagation speed coefficient and the number of affected terminals are determined. By integrating the simulated data with the vulnerability propagation rate coefficient and the number of associated terminals affected, an environmental risk coefficient is obtained for the impact of different physical environments on the vulnerability.

2. The vulnerability priority assessment method based on a large language model according to claim 1, characterized in that, The historical vulnerability assessment data is analyzed using a large language model to identify the trigger dependencies between different vulnerabilities, including: Using a large language model, the triggering conditions, impact results, and target terminal device types associated with each vulnerability are extracted from the historical vulnerability assessment data. The triggering conditions, impact results, and target terminal device types of each vulnerability are correlated and matched to identify potential trigger-related vulnerabilities that belong to the same device type and whose triggering conditions and impact results are connected. Extract the vulnerability trigger time sequence and vulnerability remediation completion time information corresponding to the potential trigger-related vulnerabilities from the historical vulnerability assessment data; Based on the vulnerability triggering time sequence and vulnerability patching completion time information, the potential triggering associated vulnerabilities are verified to determine the triggering dependency relationship between different vulnerabilities. The verification operation includes comparing the historical triggering time of the first vulnerability with the historical triggering time of the second vulnerability in the potential triggering associated vulnerabilities, comparing the vulnerability patching completion time of the first vulnerability with the historical triggering time of the second vulnerability, and determining whether the triggering time interval between the first vulnerability and the second vulnerability is within the time range of conventional vulnerability chain triggering. The first vulnerability and the second vulnerability are any different vulnerabilities in the potential triggering associated vulnerabilities.

3. The vulnerability priority assessment method based on a large language model according to claim 1, characterized in that, Based on the triggering dependencies between the different vulnerabilities, a vulnerability chain risk value is generated, including: Based on the triggering dependency relationship between the different vulnerabilities, vulnerabilities with triggering dependency relationships are identified as confirmed associated vulnerabilities, and these confirmed associated vulnerabilities are connected to form an associated vulnerability chain. Based on the vulnerability triggering frequency and vulnerability repair time corresponding to each confirmed associated vulnerability in the associated vulnerability chain, determine the triggering probability value and processing difficulty value of each confirmed associated vulnerability; The total number of vulnerabilities in the associated vulnerability chain is counted, and the chain risk bonus value is determined based on the total number of vulnerabilities. The dependency strength coefficient between adjacent confirmed associated vulnerabilities is determined based on the triggering time interval of adjacent confirmed associated vulnerabilities in the associated vulnerability chain. The vulnerability chain risk value is calculated based on the trigger probability value and processing difficulty value of each confirmed associated vulnerability in the associated vulnerability chain, the chain risk bonus value, and the dependency strength coefficient between each adjacent confirmed associated vulnerability.

4. The vulnerability priority assessment method based on a large language model according to claim 1, characterized in that, Based on the simulation data and the deployment location information of the enterprise intranet terminals, the vulnerability propagation speed coefficient and the number of affected terminals are determined, including: Based on the physical coordinates of each enterprise intranet terminal in the deployment location information, the straight-line distance between the terminal that triggered the vulnerability and the terminal that did not trigger the vulnerability is calculated. Combined with the temperature exceedance peak in the simulation data, the distance influence weight is determined. Based on the terminal network connection relationships in the deployment location information, determine the network connection tightness value; Based on the distance influence weight and the network connection tightness value, the initial speed value of the vulnerability spreading from the terminal that triggered the vulnerability to the terminal that did not trigger the vulnerability is calculated. Combined with the minimum heat dissipation efficiency value in the simulation data, the initial speed value is adjusted to obtain the vulnerability spread speed coefficient. Based on the vulnerability propagation speed coefficient, the vulnerability propagation range within a preset time period is determined. Target terminals within the vulnerability propagation range that have core business tags and are consistent with the type of terminal that triggered the vulnerability are selected for confirmation. Target terminals that are already in a vulnerability-triggered state are excluded, forming a target terminal set. The number of target terminals in the target terminal set is counted as the number of associated terminal impacts.

5. The vulnerability priority assessment method based on a large language model according to claim 1, characterized in that, Based on the real-time hardware resource data and the terminal physical attribute data, the load risk value corresponding to the enterprise intranet terminal is calculated, including: Based on the real-time CPU utilization rate, real-time memory occupancy rate, and real-time disk read / write rate in the real-time hardware resource data, and combined with the maximum CPU load, total memory capacity, and maximum disk read / write rate in the terminal physical attribute data, the basic load rate of the enterprise intranet terminal is calculated. The basic load rate includes the processor load rate, memory load rate, and disk load rate. Based on the business importance tags in the terminal physical attribute data, the business weight coefficient of the enterprise intranet terminal is determined, wherein the business weight coefficient of the enterprise intranet terminal with the core business tag is higher than the business weight coefficient of the enterprise intranet terminal with the ordinary business tag. The business-related load rate is obtained by weighted summing of the basic load rate and business weight coefficient of the enterprise intranet terminals. Based on the business-related load rate, hardware aging coefficient, and heat dissipation redundancy capability parameters in the terminal physical attribute data, a resource redundancy adjustment coefficient is determined. Combined with the business-related load rate, the load risk value corresponding to the enterprise intranet terminal is calculated.

6. The vulnerability priority assessment method based on a large language model according to claim 1, characterized in that, Based on the vulnerability chain risk value, the environmental risk coefficient, and the load risk value, the vulnerability priority in the enterprise intranet terminal is assessed, including: Based on the business importance tag in the terminal physical attribute data, determine the risk weight coefficients corresponding to the vulnerability chain risk value, the environmental risk coefficient, and the load risk value, respectively, so as to calculate the vulnerability chain risk contribution value, the environmental risk contribution value, and the load risk contribution value. Based on the vulnerability remediation time of the corresponding vulnerability in the enterprise intranet terminal in the historical vulnerability assessment data, and combined with the vulnerability propagation speed coefficient, the urgency adjustment factor is determined. Based on the vulnerability chain risk contribution value, environmental risk contribution value, and load risk contribution value, and combined with the urgency adjustment factor, the vulnerability priority score is calculated. Based on the business importance tags of the enterprise intranet terminals, a risk tolerance threshold is set, and the vulnerability priority score is compared with the risk tolerance threshold to assess the vulnerability priority in the enterprise intranet terminals.

7. A vulnerability prioritization system based on a large language model, used in the vulnerability prioritization method based on a large language model as described in any one of claims 1 to 6, characterized in that, include: The acquisition module is used to acquire real-time hardware resource data, historical vulnerability assessment data, and physical attribute data of the enterprise intranet terminals. The historical vulnerability assessment data includes the vulnerability trigger frequency and vulnerability repair time for different vulnerabilities. The parsing module is used to parse the historical vulnerability assessment data using a large language model to identify the triggering dependencies between different vulnerabilities and generate vulnerability chain risk values ​​based on the triggering dependencies between different vulnerabilities. The simulation module is used to simulate the environment of the enterprise intranet terminal and the changes in the operating status of the enterprise intranet terminal after the vulnerability is triggered, based on the terminal's physical attribute data and using a digital twin model, so as to generate an environmental risk coefficient. The calculation module is used to calculate the load risk value corresponding to the enterprise intranet terminal based on the real-time hardware resource data and the terminal physical attribute data; The assessment module is used to assess the vulnerability priority in the enterprise intranet terminal based on the vulnerability chain risk value, the environmental risk coefficient, and the load risk value.

8. A computing device, characterized in that, It includes a processing component and a storage component; the storage component stores one or more computer instructions; the one or more computer instructions are invoked and executed by the processing component to implement a vulnerability priority assessment method based on a large language model as described in any one of claims 1 to 6.

9. A computer storage medium, characterized in that, The system contains a computer program that, when executed by a computer, implements a vulnerability priority assessment method based on a large language model as described in any one of claims 1 to 6.

Citation Information

Patent Citations

  • College network security deduction integrated platform based on digital twinning

    CN120186035A

  • Vulnerability association detection method and system applied to power system

    CN120614194A

  • Vulnerability processing method and device, equipment and medium

    CN120951339A